Oracle E-Business Suite Credentials Disclosure

high Web App Scanning Plugin ID 115318

Synopsis

Oracle E-Business Suite Credentials Disclosure

Description

Oracle E-Business Suite (EBS) exposes a JTF (Java Technology Foundation) repository descriptor file, `jtfwrepo.xml`, under the `/OA_HTML` virtual directory. When this file is accessible without authentication, it discloses repository configuration including cleartext credentials contained in the `password=` attributes of its `<PUSR_LIST>` elements.

An unauthenticated, remote attacker can retrieve this file to obtain valid credentials for the Oracle E-Business Suite environment. These credentials may be leveraged to authenticate to the application or backing services, leading to further sensitive information disclosure and potential compromise of the EBS instance.

Solution

Restrict public access to the `/OA_HTML/jtfwrepo.xml` file at the web server or reverse proxy layer, and apply Oracle's E-Business Suite security hardening guidance. Any credentials exposed through this file must be considered compromised and rotated.

See Also

https://docs.oracle.com/cd/E26401_01/doc.122/e22952/toc.htm

Plugin Details

Severity: High

ID: 115318

Type: Check Based

Published: 7/28/2026

Updated: 7/28/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: High

Score: 7.3

Percentile: 0

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: High

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information